8.3

CVE-2020-13321

Exploit
A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab Version < 12.10.13
Gitlab ≫ GitLab Version >= 13.0.0 < 13.0.8
Gitlab ≫ GitLab Version >= 13.1.0 < 13.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.42% 0.694
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.3 2.8 5.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
cve@gitlab.com 8.3 2.8 5.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13321.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/25751
Vendor Advisory
Exploit